IBM Support

IV84742: VULNERABILITY - CSRF - POST ACTIONS THAT DO NOT REQUIRE A SECURITY TOKEN

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as fixed if next.

Error description

  • Some state changing actions are not having the security token
    properly enforced, which can be a potential CSRF exposure.
    CSRF attacks with no token can generally be addressed by using
    the KNOWN_REFERRER_LIST property in TRIRIGAWEB.properties file.
    

Local fix

  • No
    

Problem summary

  • Added security validation to several pages through out the
    platform.
    

Problem conclusion

  • The issue has been resolved. This is targeted to the 1H2016
    release as well as the 3.4.2.4 and 3.5.0.1 fix packs.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV84742

  • Reported component name

    TRI APP PLTFM R

  • Reported component ID

    5725F26RE

  • Reported release

    350

  • Status

    CLOSED FIN

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2016-05-12

  • Closed date

    2016-05-16

  • Last modified date

    2016-05-16

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • 999
    

Fix information

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSHEB3","label":"IBM TRIRIGA Application Platform"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"350","Edition":"","Line of Business":{"code":"LOB59","label":"Sustainability Software"}}]

Document Information

Modified date:
30 March 2022